Hi all,
I'm having a problem setting up a site to site with a remote peer. This is the last one of 6 we have moved over from our ASA to the firewalls. I've typed this from my phone, sorry for the basic formatting.
The specs of the site to site are:
- Remote gateway: 142.152.123.66
- Remote service over HTTPS: 142.152.123.67
- Local encryption domain: 192.168.199.48/28
- Access is required from our 10/8 internal network.
NAT Rule, SRC:10/8 DST:142.152.123.67 HIDE: 192.168.199.49
IKEv2 is negotiating ok.
The gateway is setup with per community domains. Tried per subnet and per gateway tunnel sharing.
Community:
- Local: Group 10/8 & 192.168.199.48/28
- Remote: 142.152.123.67
I have lab'd it up at home with the same IPs, apart from the remote peer, and it just works.
When I fw monitor the connection, I can see the packets go to the remote peer via my external interface, OE, over udp50 after the NAT.
The work fw sends the packet after NAT to the remote gateway over UDP500 through the external interface (O).
P.s. I have read every article on 3rd party vpns. Unless I'm not understanding the fault / resolution, I can't find the answer in there.
Could it have anything to do with the remote peer and remote endpoint both being on the internet and the IPs next to eachother (supernetting)?
Thanks in advanced
Rich